BIG security issue adding account with PLAID

Topic summary

A critical security vulnerability has been identified when linking bank accounts through Plaid integration.

The Issue:

  • Users attempting to add their bank accounts via Plaid are having incorrect accounts (belonging to other people) added to their Shopify Payments instead
  • The problem persists even after support resets the connection, occurring repeatedly when users retry the Plaid linking process

Current Status:

  • One user spent several days and multiple hours with support to get a reset, but the issue recurred immediately
  • At least one other merchant has experienced the identical problem
  • The discussion remains open with no confirmed resolution
  • Users are seeking guidance on how Shopify support addressed this security breach
Summarized with AI on October 31. AI used: claude-sonnet-4-5-20250929.

I’ve been trying for several days to get Shopity to remove a Payments account that’s not mine. It turns out I was adding my bank account using Plaid and when I did, Shopify and Plaid added a bank account that’s not mine. I asked for a reset of this, which I managed to do after several days and hours talking to support… but when I tried to add my account using Plaid the same thing happened. This is a huge security risk on the part of Shopify and Plaid.

Same thing happened to me tonight. What did Shopify do to help you fix it?